CVE-2026-65801
Microsoft — Microsoft Exchange Online Elevation of Privilege Vulnerability
What EVULNABLE says
EVULNABLE Risk · priority
13/100
Elevated
Intelligence coverage 80/100 — no Microsoft Exploitability Index, no ransomware association data, no CISA KEV listing date
The priority band answers “how soon”, not “how bad” — see Methodology for what it weighs and where it abstains.
The evidence behind it
| Measure | Value | Source |
|---|---|---|
| CVSS base score | 10.0 | — |
| FIRST EPSS | 0.005 (41.6th pctl) | FIRST |
| Actively exploited | Not confirmed | Patch Tuesday |
The primary records
This page is an opinion about urgency. Where it and a source of record disagree, the source of record is the record.